<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

	<channel>
		<title>List Archives</title>
		<link>http://www.activedir.org/ListArchives/tabid/55/forumid/1/view/topics/Default.aspx</link>
		<description>The activedir.org mail list archives</description>
		<language>en-US</language>
		<generator>ActiveForums  3.6</generator>
		<copyright>Copyright 2009 ActiveDir.org</copyright>
		<webMaster>info@mail.activedir.org</webMaster>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/ListArchives" type="application/rss+xml" /><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2FListArchives" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FListArchives" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2FListArchives" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/ListArchives" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2FListArchives" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2FListArchives" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2FListArchives" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><item>
			<title>[ActiveDir] cannot log w2k3 trusting domain, account in the w2k3 
 trusted domain</title>
			<description>Does anyone have pass trought this cenario? &lt;br&gt;  &lt;br&gt; You cannot log on to a computer in the Windows Server 2003 trusting domain &lt;br&gt; by using a user account in the Windows Server 2003 trusted domain &lt;br&gt;  &lt;br&gt; Both domains in a trust relationship share a password. This password is &lt;br&gt; stored in the Trusted Domain Object (TDO) in Active Directory. As part of &lt;br&gt; the account maintenance process, the trusting domain controller changes the &lt;br&gt; password that is stored in the TDO every 30 days. If the changed trust &lt;br&gt; password has not replicated to all domain controllers *in an hour*, some &lt;br&gt; domain controllers still use the old trust password. Therefore, the &lt;br&gt; authentication fails. &lt;br&gt;  &lt;br&gt; I have sites links with 180min, so have this prob... &lt;br&gt;  &lt;br&gt; http://support.microsoft.com/kb/941761/en-us &lt;br&gt;  &lt;br&gt; How can I reset the trust password for a two way trust ? &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/27R0QaIgBGI/Default.aspx</link>
			<author>jppmendes</author>
			<pubDate>Sun, 05 Jul 2009 10:06:31 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35853/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>[ActiveDir] cannot log w2k3 trusting domain, account in the w2k3 trusted domain</title>
			<description>Does anyone have pass trought this cenario? &lt;br&gt;  &lt;br&gt; You cannot log on to a computer in the Windows Server 2003 trusting domain &lt;br&gt; by using a user account in the Windows Server 2003 trusted domain &lt;br&gt;  &lt;br&gt; Both domains in a trust relationship share a password. This password is &lt;br&gt; stored in the Trusted Domain Object (TDO) in Active Directory. As part of &lt;br&gt; the account maintenance process, the trusting domain controller changes the &lt;br&gt; password that is stored in the TDO every 30 days. If the changed trust &lt;br&gt; password has not replicated to all domain controllers *in an hour*, some &lt;br&gt; domain controllers still use the old trust password. Therefore, the &lt;br&gt; authentication fails. &lt;br&gt;  &lt;br&gt; I have sites links with 180min, so have this prob... &lt;br&gt;  &lt;br&gt; http://support.microsoft.com/kb/941761/en-us &lt;br&gt;  &lt;br&gt; How can I reset the trust password for a two way trust ? &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/axNfImsxdJU/Default.aspx</link>
			<author>jppmendes</author>
			<pubDate>Sun, 05 Jul 2009 09:46:16 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35852/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>RE: [ActiveDir] Exchange and Active Directory authentication
 confusion</title>
			<description>Yeah that design makes no sense to me given what I imagine your environment looks like (having spent a lot of time in K-12). &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt; Brian Desmond &lt;br&gt; brian@briandesmond.com &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 7:20 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;   I had a hard time describing what the consultant did. The domain design looks like this: &lt;br&gt;  &lt;br&gt; |Administrative Root domain &lt;br&gt; |High school domain &lt;br&gt; |Middle school domain &lt;br&gt; |Elementary school domain &lt;br&gt;  &lt;br&gt; As opposed to a Parent Administraive Root domain  with the other domains being branches of the root domain in a "tree". By forest domain design I mean just how the domains are arranged visually in the forest.  The consultant's design does not have child or branch domains at least not visually. &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Crawford, Scott &lt;br&gt; Sent: Thursday, July 02, 2009 2:17 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; That was my first thought too, but the fact that he says "forest domain design" seems to imply that he sees a distinction.  Of course, we could just wait til the OP relies. &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Rick Sheikh &lt;br&gt; Sent: Thursday, July 02, 2009 3:57 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: Re: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; Didn't Dave mean separate forests by "All of the domains are flat rather than parent child hierarchical. The explanation for this was better security." ? &lt;br&gt; On Thu, Jul 2, 2009 at 3:48 PM, Paul Bergson (ALLETE) &amp;lt;pbergson@allete.com&amp;lt;mailto:pbergson@allete.com&amp;gt;&amp;gt; wrote: &lt;br&gt;  &lt;br&gt; Agree with Brian. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Security boundary is the forest not the domain. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Paul &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Brian Desmond &lt;br&gt; Sent: Thursday, July 02, 2009 3:17 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Said explanation is 100% wrong. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Brian Desmond &lt;br&gt;  &lt;br&gt; brian@briandesmond.com&amp;lt;mailto:brian@briandesmond.com&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt;  &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 3:13 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;   This forest domain design was done before my time by a consultant. It is a very odd design. All of the domains are flat rather than parent child hierarchical. The explanation for this was better security. If anyone compromised one domain it would be more difficult to get access to the other domains. I am somewhat skeptical of this explanation. This is a K-12 environment so there is the possibility of malicious end users. &lt;br&gt;  &lt;br&gt;   The next iteration to 2008 server I hope to migrate to the one forest one domain design that seems to be the consensus for  better and easier  maintenance? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of joe &lt;br&gt; Sent: Thursday, July 02, 2009 5:26 AM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Have a domain controller for every domain you want authentication to be available for in the locations you want it available. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Alternately, get collapse the six domains down to one, you likely don't really need six domains. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 6:31 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;   Thank you for clearing this up for me. Another hole in my knowledge has been patched! Are there any workarounds for this limitation? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of joe &lt;br&gt; Sent: Wednesday, July 01, 2009 3:03 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; The security information to authenticate/authorize a user is not replicated forest wide. A user can only be authenticated by a domain controller for the domain they are a member of. So say you have one DC for DomainXYZ and it went down, even though you have 100 DCs for DomainPDQ not a single DomainXYZ user could logon. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 5:51 PM &lt;br&gt; To: ActiveDir@mail.activedir.org&amp;lt;mailto:ActiveDir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;    I am having some confusion about Exchange authentication and Active Directory. We have a single forest with six domains that is Windows server 2003 R2SP2. The Exchange Server (2003) is in the root domain on a server that is not a domain controller. Two of the domains in our forest are remote sites connected via a T1 WAN link. &lt;br&gt;  &lt;br&gt;   Recently the T1 link to one of our sites went down. As a result no one at the remote site could log into the Exchange server. This is understandable when the employees are on the site with the dead T1 connection. What confuses me is that none of the employees at this site could login to e-mail remotely via Outlook Web Access. Now if user accounts are replicated forest-wide? Then why could the users at the disconnected remote site not log into OWA via another domain controller (which authenticates users for the unreacheable remote server) not disconnected due to a out of service T1 WAN link? &lt;br&gt;  &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/jG0MgDTwdlo/Default.aspx</link>
			<author>bdesmond</author>
			<pubDate>Fri, 03 Jul 2009 02:39:59 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35845/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>RE: [ActiveDir] Exchange and Active Directory authentication  confusion</title>
			<description>  I had a hard time describing what the consultant did. The domain design &lt;br&gt; looks like this:  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; |Administrative Root domain &lt;br&gt;  &lt;br&gt; |High school domain &lt;br&gt;  &lt;br&gt; |Middle school domain &lt;br&gt;  &lt;br&gt; |Elementary school domain &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; As opposed to a Parent Administraive Root domain  with the other domains &lt;br&gt; being branches of the root domain in a "tree". By forest domain design I &lt;br&gt; mean just how the domains are arranged visually in the forest.  The &lt;br&gt; consultant's design does not have child or branch domains at least not &lt;br&gt; visually. &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Crawford, Scott &lt;br&gt; Sent: Thursday, July 02, 2009 2:17 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; That was my first thought too, but the fact that he says "forest domain &lt;br&gt; design" seems to imply that he sees a distinction.  Of course, we could just &lt;br&gt; wait til the OP relies. &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Rick Sheikh &lt;br&gt; Sent: Thursday, July 02, 2009 3:57 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: Re: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Didn't Dave mean separate forests by "All of the domains are flat rather &lt;br&gt; than parent child hierarchical. The explanation for this was better &lt;br&gt; security." ? &lt;br&gt;  &lt;br&gt; On Thu, Jul 2, 2009 at 3:48 PM, Paul Bergson (ALLETE) &amp;lt;pbergson@allete.com&amp;gt; &lt;br&gt; wrote: &lt;br&gt;  &lt;br&gt; Agree with Brian.   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Security boundary is the forest not the domain. &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Paul &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Brian Desmond &lt;br&gt; Sent: Thursday, July 02, 2009 3:17 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Said explanation is 100% wrong.  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Brian Desmond &lt;br&gt;  &lt;br&gt; brian@briandesmond.com &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed -  &amp;lt;http://www.briandesmond.com/ad4/&amp;gt; &lt;br&gt; http://www.briandesmond.com/ad4/ &lt;br&gt;  &lt;br&gt; Microsoft MVP -  &amp;lt;https://mvp.support.microsoft.com/profile/Brian&amp;gt; &lt;br&gt; https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 3:13 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   This forest domain design was done before my time by a consultant. It is a &lt;br&gt; very odd design. All of the domains are flat rather than parent child &lt;br&gt; hierarchical. The explanation for this was better security. If anyone &lt;br&gt; compromised one domain it would be more difficult to get access to the other &lt;br&gt; domains. I am somewhat skeptical of this explanation. This is a K-12 &lt;br&gt; environment so there is the possibility of malicious end users.   &lt;br&gt;  &lt;br&gt;   The next iteration to 2008 server I hope to migrate to the one forest one &lt;br&gt; domain design that seems to be the consensus for  better and easier &lt;br&gt; maintenance? &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of joe &lt;br&gt; Sent: Thursday, July 02, 2009 5:26 AM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Have a domain controller for every domain you want authentication to be &lt;br&gt; available for in the locations you want it available.  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Alternately, get collapse the six domains down to one, you likely don't &lt;br&gt; really need six domains. &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - &lt;br&gt; http://www.joeware.net/win/ad4e.htm  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   _____   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 6:31 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   Thank you for clearing this up for me. Another hole in my knowledge has &lt;br&gt; been patched! Are there any workarounds for this limitation? &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of joe &lt;br&gt; Sent: Wednesday, July 01, 2009 3:03 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; The security information to authenticate/authorize a user is not replicated &lt;br&gt; forest wide. A user can only be authenticated by a domain controller for the &lt;br&gt; domain they are a member of. So say you have one DC for DomainXYZ and it &lt;br&gt; went down, even though you have 100 DCs for DomainPDQ not a single DomainXYZ &lt;br&gt; user could logon.  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - &lt;br&gt; http://www.joeware.net/win/ad4e.htm  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   _____   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 5:51 PM &lt;br&gt; To: ActiveDir@mail.activedir.org &lt;br&gt; Subject: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;    I am having some confusion about Exchange authentication and Active &lt;br&gt; Directory. We have a single forest with six domains that is Windows server &lt;br&gt; 2003 R2SP2. The Exchange Server (2003) is in the root domain on a server &lt;br&gt; that is not a domain controller. Two of the domains in our forest are remote &lt;br&gt; sites connected via a T1 WAN link.  &lt;br&gt;  &lt;br&gt;   Recently the T1 link to one of our sites went down. As a result no one at &lt;br&gt; the remote site could log into the Exchange server. This is understandable &lt;br&gt; when the employees are on the site with the dead T1 connection. What &lt;br&gt; confuses me is that none of the employees at this site could login to e-mail &lt;br&gt; remotely via Outlook Web Access. Now if user accounts are replicated &lt;br&gt; forest-wide? Then why could the users at the disconnected remote site not &lt;br&gt; log into OWA via another domain controller (which authenticates users for &lt;br&gt; the unreacheable remote server) not disconnected due to a out of service T1 &lt;br&gt; WAN link?  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/vlv5ILe78fA/Default.aspx</link>
			<author>ddriggs</author>
			<pubDate>Fri, 03 Jul 2009 01:20:34 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35844/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>RE: [ActiveDir] Exchange and Active Directory authentication  confusion</title>
			<description>That was my first thought too, but the fact that he says "forest domain &lt;br&gt; design" seems to imply that he sees a distinction.  Of course, we could &lt;br&gt; just wait til the OP relies. &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Rick Sheikh &lt;br&gt; Sent: Thursday, July 02, 2009 3:57 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: Re: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Didn't Dave mean separate forests by "All of the domains are flat rather &lt;br&gt; than parent child hierarchical. The explanation for this was better &lt;br&gt; security." ? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; On Thu, Jul 2, 2009 at 3:48 PM, Paul Bergson (ALLETE) &lt;br&gt; &amp;lt;pbergson@allete.com&amp;gt; wrote: &lt;br&gt;  &lt;br&gt; Agree with Brian.   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Security boundary is the forest not the domain. &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Paul &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Brian Desmond &lt;br&gt; Sent: Thursday, July 02, 2009 3:17 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Said explanation is 100% wrong.  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Brian Desmond &lt;br&gt;  &lt;br&gt; brian@briandesmond.com &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt; &amp;lt;http://www.briandesmond.com/ad4/&amp;gt;  &lt;br&gt;  &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt; &amp;lt;https://mvp.support.microsoft.com/profile/Brian&amp;gt;  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 3:13 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   This forest domain design was done before my time by a consultant. It &lt;br&gt; is a very odd design. All of the domains are flat rather than parent &lt;br&gt; child hierarchical. The explanation for this was better security. If &lt;br&gt; anyone compromised one domain it would be more difficult to get access &lt;br&gt; to the other domains. I am somewhat skeptical of this explanation. This &lt;br&gt; is a K-12 environment so there is the possibility of malicious end &lt;br&gt; users.   &lt;br&gt;  &lt;br&gt;   The next iteration to 2008 server I hope to migrate to the one forest &lt;br&gt; one domain design that seems to be the consensus for  better and easier &lt;br&gt; maintenance? &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of joe &lt;br&gt; Sent: Thursday, July 02, 2009 5:26 AM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Have a domain controller for every domain you want authentication to be &lt;br&gt; available for in the locations you want it available.  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; Alternately, get collapse the six domains down to one, you likely don't &lt;br&gt; really need six domains. &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - &lt;br&gt; http://www.joeware.net/win/ad4e.htm  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 6:31 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   Thank you for clearing this up for me. Another hole in my knowledge &lt;br&gt; has been patched! Are there any workarounds for this limitation? &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of joe &lt;br&gt; Sent: Wednesday, July 01, 2009 3:03 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; The security information to authenticate/authorize a user is not &lt;br&gt; replicated forest wide. A user can only be authenticated by a domain &lt;br&gt; controller for the domain they are a member of. So say you have one DC &lt;br&gt; for DomainXYZ and it went down, even though you have 100 DCs for &lt;br&gt; DomainPDQ not a single DomainXYZ user could logon.  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - &lt;br&gt; http://www.joeware.net/win/ad4e.htm  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org &lt;br&gt; [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 5:51 PM &lt;br&gt; To: ActiveDir@mail.activedir.org &lt;br&gt; Subject: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; confusion &lt;br&gt;  &lt;br&gt;    I am having some confusion about Exchange authentication and Active &lt;br&gt; Directory. We have a single forest with six domains that is Windows &lt;br&gt; server 2003 R2SP2. The Exchange Server (2003) is in the root domain on a &lt;br&gt; server that is not a domain controller. Two of the domains in our forest &lt;br&gt; are remote sites connected via a T1 WAN link.  &lt;br&gt;  &lt;br&gt;   Recently the T1 link to one of our sites went down. As a result no one &lt;br&gt; at the remote site could log into the Exchange server. This is &lt;br&gt; understandable when the employees are on the site with the dead T1 &lt;br&gt; connection. What confuses me is that none of the employees at this site &lt;br&gt; could login to e-mail remotely via Outlook Web Access. Now if user &lt;br&gt; accounts are replicated forest-wide? Then why could the users at the &lt;br&gt; disconnected remote site not log into OWA via another domain controller &lt;br&gt; (which authenticates users for the unreacheable remote server) not &lt;br&gt; disconnected due to a out of service T1 WAN link?  &lt;br&gt;  &lt;br&gt;   &lt;br&gt;  &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/MNeTnyIWWqM/Default.aspx</link>
			<author>CrawfordS</author>
			<pubDate>Thu, 02 Jul 2009 22:19:26 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35840/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>RE: [ActiveDir] Exchange and Active Directory authentication
 confusion</title>
			<description>I took it as a single forest with disjoint name space for each domain. &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt; Paul &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Brian Desmond &lt;br&gt; Sent: Thursday, July 02, 2009 4:00 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; I just got the impression he as 6 domain trees in his forest based on that note and the original post. &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt; Brian Desmond &lt;br&gt; brian@briandesmond.com &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Rick Sheikh &lt;br&gt; Sent: Thursday, July 02, 2009 3:57 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: Re: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; Didn't Dave mean separate forests by "All of the domains are flat rather than parent child hierarchical. The explanation for this was better security." ? &lt;br&gt; On Thu, Jul 2, 2009 at 3:48 PM, Paul Bergson (ALLETE) &amp;lt;pbergson@allete.com&amp;lt;mailto:pbergson@allete.com&amp;gt;&amp;gt; wrote: &lt;br&gt;  &lt;br&gt; Agree with Brian. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Security boundary is the forest not the domain. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Paul &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Brian Desmond &lt;br&gt; Sent: Thursday, July 02, 2009 3:17 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Said explanation is 100% wrong. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Brian Desmond &lt;br&gt;  &lt;br&gt; brian@briandesmond.com&amp;lt;mailto:brian@briandesmond.com&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt;  &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 3:13 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;   This forest domain design was done before my time by a consultant. It is a very odd design. All of the domains are flat rather than parent child hierarchical. The explanation for this was better security. If anyone compromised one domain it would be more difficult to get access to the other domains. I am somewhat skeptical of this explanation. This is a K-12 environment so there is the possibility of malicious end users. &lt;br&gt;  &lt;br&gt;   The next iteration to 2008 server I hope to migrate to the one forest one domain design that seems to be the consensus for  better and easier  maintenance? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of joe &lt;br&gt; Sent: Thursday, July 02, 2009 5:26 AM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Have a domain controller for every domain you want authentication to be available for in the locations you want it available. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Alternately, get collapse the six domains down to one, you likely don't really need six domains. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 6:31 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;   Thank you for clearing this up for me. Another hole in my knowledge has been patched! Are there any workarounds for this limitation? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of joe &lt;br&gt; Sent: Wednesday, July 01, 2009 3:03 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; The security information to authenticate/authorize a user is not replicated forest wide. A user can only be authenticated by a domain controller for the domain they are a member of. So say you have one DC for DomainXYZ and it went down, even though you have 100 DCs for DomainPDQ not a single DomainXYZ user could logon. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 5:51 PM &lt;br&gt; To: ActiveDir@mail.activedir.org&amp;lt;mailto:ActiveDir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;    I am having some confusion about Exchange authentication and Active Directory. We have a single forest with six domains that is Windows server 2003 R2SP2. The Exchange Server (2003) is in the root domain on a server that is not a domain controller. Two of the domains in our forest are remote sites connected via a T1 WAN link. &lt;br&gt;  &lt;br&gt;   Recently the T1 link to one of our sites went down. As a result no one at the remote site could log into the Exchange server. This is understandable when the employees are on the site with the dead T1 connection. What confuses me is that none of the employees at this site could login to e-mail remotely via Outlook Web Access. Now if user accounts are replicated forest-wide? Then why could the users at the disconnected remote site not log into OWA via another domain controller (which authenticates users for the unreacheable remote server) not disconnected due to a out of service T1 WAN link? &lt;br&gt;  &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/peOLBRjiprg/Default.aspx</link>
			<author>pbbergs</author>
			<pubDate>Thu, 02 Jul 2009 22:15:22 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35839/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>RE: [ActiveDir] Exchange and Active Directory authentication
 confusion</title>
			<description>Actually probably seven as you would have ended up needing an Exchange resource forest probably. &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt; Brian Desmond &lt;br&gt; brian@briandesmond.com &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 4:03 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;   So the consultant really needed to create gulp six different forests? I would never do that. &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Paul Bergson (ALLETE) &lt;br&gt; Sent: Thursday, July 02, 2009 1:48 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; Agree with Brian. &lt;br&gt;  &lt;br&gt; Security boundary is the forest not the domain. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt; Paul &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Brian Desmond &lt;br&gt; Sent: Thursday, July 02, 2009 3:17 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; Said explanation is 100% wrong. &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt; Brian Desmond &lt;br&gt; brian@briandesmond.com &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 3:13 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;   This forest domain design was done before my time by a consultant. It is a very odd design. All of the domains are flat rather than parent child hierarchical. The explanation for this was better security. If anyone compromised one domain it would be more difficult to get access to the other domains. I am somewhat skeptical of this explanation. This is a K-12 environment so there is the possibility of malicious end users. &lt;br&gt;   The next iteration to 2008 server I hope to migrate to the one forest one domain design that seems to be the consensus for  better and easier  maintenance? &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of joe &lt;br&gt; Sent: Thursday, July 02, 2009 5:26 AM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; Have a domain controller for every domain you want authentication to be available for in the locations you want it available. &lt;br&gt;  &lt;br&gt; Alternately, get collapse the six domains down to one, you likely don't really need six domains. &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 6:31 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;   Thank you for clearing this up for me. Another hole in my knowledge has been patched! Are there any workarounds for this limitation? &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of joe &lt;br&gt; Sent: Wednesday, July 01, 2009 3:03 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; The security information to authenticate/authorize a user is not replicated forest wide. A user can only be authenticated by a domain controller for the domain they are a member of. So say you have one DC for DomainXYZ and it went down, even though you have 100 DCs for DomainPDQ not a single DomainXYZ user could logon. &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 5:51 PM &lt;br&gt; To: ActiveDir@mail.activedir.org &lt;br&gt; Subject: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;    I am having some confusion about Exchange authentication and Active Directory. We have a single forest with six domains that is Windows server 2003 R2SP2. The Exchange Server (2003) is in the root domain on a server that is not a domain controller. Two of the domains in our forest are remote sites connected via a T1 WAN link. &lt;br&gt;   Recently the T1 link to one of our sites went down. As a result no one at the remote site could log into the Exchange server. This is understandable when the employees are on the site with the dead T1 connection. What confuses me is that none of the employees at this site could login to e-mail remotely via Outlook Web Access. Now if user accounts are replicated forest-wide? Then why could the users at the disconnected remote site not log into OWA via another domain controller (which authenticates users for the unreacheable remote server) not disconnected due to a out of service T1 WAN link? &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/Cv2phTDRjfg/Default.aspx</link>
			<author>bdesmond</author>
			<pubDate>Thu, 02 Jul 2009 22:13:21 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35838/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>RE: [ActiveDir] Exchange and Active Directory authentication
 confusion</title>
			<description>I just got the impression he as 6 domain trees in his forest based on that note and the original post. &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt; Brian Desmond &lt;br&gt; brian@briandesmond.com &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Rick Sheikh &lt;br&gt; Sent: Thursday, July 02, 2009 3:57 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: Re: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; Didn't Dave mean separate forests by "All of the domains are flat rather than parent child hierarchical. The explanation for this was better security." ? &lt;br&gt;  &lt;br&gt; On Thu, Jul 2, 2009 at 3:48 PM, Paul Bergson (ALLETE) &amp;lt;pbergson@allete.com&amp;lt;mailto:pbergson@allete.com&amp;gt;&amp;gt; wrote: &lt;br&gt;  &lt;br&gt; Agree with Brian. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Security boundary is the forest not the domain. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Paul &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Brian Desmond &lt;br&gt; Sent: Thursday, July 02, 2009 3:17 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Said explanation is 100% wrong. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt;  &lt;br&gt; Brian Desmond &lt;br&gt;  &lt;br&gt; brian@briandesmond.com&amp;lt;mailto:brian@briandesmond.com&amp;gt; &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt;  &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 3:13 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;   This forest domain design was done before my time by a consultant. It is a very odd design. All of the domains are flat rather than parent child hierarchical. The explanation for this was better security. If anyone compromised one domain it would be more difficult to get access to the other domains. I am somewhat skeptical of this explanation. This is a K-12 environment so there is the possibility of malicious end users. &lt;br&gt;  &lt;br&gt;   The next iteration to 2008 server I hope to migrate to the one forest one domain design that seems to be the consensus for  better and easier  maintenance? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of joe &lt;br&gt; Sent: Thursday, July 02, 2009 5:26 AM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Have a domain controller for every domain you want authentication to be available for in the locations you want it available. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Alternately, get collapse the six domains down to one, you likely don't really need six domains. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 6:31 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;   Thank you for clearing this up for me. Another hole in my knowledge has been patched! Are there any workarounds for this limitation? &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of joe &lt;br&gt; Sent: Wednesday, July 01, 2009 3:03 PM &lt;br&gt; To: activedir@mail.activedir.org&amp;lt;mailto:activedir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; The security information to authenticate/authorize a user is not replicated forest wide. A user can only be authenticated by a domain controller for the domain they are a member of. So say you have one DC for DomainXYZ and it went down, even though you have 100 DCs for DomainPDQ not a single DomainXYZ user could logon. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt;  &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt; [mailto:activedir-owner@mail.activedir.org&amp;lt;mailto:activedir-owner@mail.activedir.org&amp;gt;] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 5:51 PM &lt;br&gt; To: ActiveDir@mail.activedir.org&amp;lt;mailto:ActiveDir@mail.activedir.org&amp;gt; &lt;br&gt; Subject: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;    I am having some confusion about Exchange authentication and Active Directory. We have a single forest with six domains that is Windows server 2003 R2SP2. The Exchange Server (2003) is in the root domain on a server that is not a domain controller. Two of the domains in our forest are remote sites connected via a T1 WAN link. &lt;br&gt;  &lt;br&gt;   Recently the T1 link to one of our sites went down. As a result no one at the remote site could log into the Exchange server. This is understandable when the employees are on the site with the dead T1 connection. What confuses me is that none of the employees at this site could login to e-mail remotely via Outlook Web Access. Now if user accounts are replicated forest-wide? Then why could the users at the disconnected remote site not log into OWA via another domain controller (which authenticates users for the unreacheable remote server) not disconnected due to a out of service T1 WAN link? &lt;br&gt;  &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/ZJQ7GwICOWo/Default.aspx</link>
			<author>bdesmond</author>
			<pubDate>Thu, 02 Jul 2009 22:01:08 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35835/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>Re: [ActiveDir] Exchange and Active Directory authentication 
 confusion</title>
			<description>Didn't Dave mean separate forests by "All of the domains are flat rather &lt;br&gt; than parent child hierarchical. The explanation for this was better &lt;br&gt; security." ? &lt;br&gt;  &lt;br&gt;  &lt;br&gt; On Thu, Jul 2, 2009 at 3:48 PM, Paul Bergson (ALLETE) &lt;br&gt; &amp;lt;pbergson@allete.com&amp;gt;wrote: &lt;br&gt;  &lt;br&gt; &amp;gt;  Agree with Brian. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Security boundary is the forest not the domain. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Thanks &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Paul &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* activedir-owner@mail.activedir.org [mailto: &lt;br&gt; &amp;gt; activedir-owner@mail.activedir.org] *On Behalf Of *Brian Desmond &lt;br&gt; &amp;gt; *Sent:* Thursday, July 02, 2009 3:17 PM &lt;br&gt; &amp;gt; *To:* activedir@mail.activedir.org &lt;br&gt; &amp;gt; *Subject:* RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; &amp;gt; confusion &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Said explanation is 100% wrong. * &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; * * &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Thanks,* &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Brian Desmond* &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *brian@briandesmond.com* &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; * * &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *c - 312.731.3132* &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; * * &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Active Directory, 4th Ed - http://www.briandesmond.com/ad4/* &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian* &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; * * &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* activedir-owner@mail.activedir.org [mailto: &lt;br&gt; &amp;gt; activedir-owner@mail.activedir.org] *On Behalf Of *Dave &lt;br&gt; &amp;gt; *Sent:* Thursday, July 02, 2009 3:13 PM &lt;br&gt; &amp;gt; *To:* activedir@mail.activedir.org &lt;br&gt; &amp;gt; *Subject:* RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; &amp;gt; confusion &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt;   This forest domain design was done before my time by a consultant. It is &lt;br&gt; &amp;gt; a very odd design. All of the domains are flat rather than parent child &lt;br&gt; &amp;gt; hierarchical. The explanation for this was better security. If anyone &lt;br&gt; &amp;gt; compromised one domain it would be more difficult to get access to the other &lt;br&gt; &amp;gt; domains. I am somewhat skeptical of this explanation. This is a K-12 &lt;br&gt; &amp;gt; environment so there is the possibility of malicious end users. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt;   The next iteration to 2008 server I hope to migrate to the one forest one &lt;br&gt; &amp;gt; domain design that seems to be the consensus for  better and easier &lt;br&gt; &amp;gt;  maintenance? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* activedir-owner@mail.activedir.org [mailto: &lt;br&gt; &amp;gt; activedir-owner@mail.activedir.org] *On Behalf Of *joe &lt;br&gt; &amp;gt; *Sent:* Thursday, July 02, 2009 5:26 AM &lt;br&gt; &amp;gt; *To:* activedir@mail.activedir.org &lt;br&gt; &amp;gt; *Subject:* RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; &amp;gt; confusion &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Have a domain controller for every domain you want authentication to be &lt;br&gt; &amp;gt; available for in the locations you want it available. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; Alternately, get collapse the six domains down to one, you likely don't &lt;br&gt; &amp;gt; really need six domains. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; -- &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; O'Reilly Active Directory Fourth Edition - &lt;br&gt; &amp;gt; http://www.joeware.net/win/ad4e.htm &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt;  ------------------------------ &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* activedir-owner@mail.activedir.org [mailto: &lt;br&gt; &amp;gt; activedir-owner@mail.activedir.org] *On Behalf Of *Dave &lt;br&gt; &amp;gt; *Sent:* Wednesday, July 01, 2009 6:31 PM &lt;br&gt; &amp;gt; *To:* activedir@mail.activedir.org &lt;br&gt; &amp;gt; *Subject:* RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; &amp;gt; confusion &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt;   Thank you for clearing this up for me. Another hole in my knowledge has &lt;br&gt; &amp;gt; been patched! Are there any workarounds for this limitation? &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* activedir-owner@mail.activedir.org [mailto: &lt;br&gt; &amp;gt; activedir-owner@mail.activedir.org] *On Behalf Of *joe &lt;br&gt; &amp;gt; *Sent:* Wednesday, July 01, 2009 3:03 PM &lt;br&gt; &amp;gt; *To:* activedir@mail.activedir.org &lt;br&gt; &amp;gt; *Subject:* RE: [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; &amp;gt; confusion &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; The security information to authenticate/authorize a user is not replicated &lt;br&gt; &amp;gt; forest wide. A user can only be authenticated by a domain controller for the &lt;br&gt; &amp;gt; domain they are a member of. So say you have one DC for DomainXYZ and it &lt;br&gt; &amp;gt; went down, even though you have 100 DCs for DomainPDQ not a single DomainXYZ &lt;br&gt; &amp;gt; user could logon. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; -- &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; O'Reilly Active Directory Fourth Edition - &lt;br&gt; &amp;gt; http://www.joeware.net/win/ad4e.htm &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt;  ------------------------------ &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt; *From:* activedir-owner@mail.activedir.org [mailto: &lt;br&gt; &amp;gt; activedir-owner@mail.activedir.org] *On Behalf Of *Dave &lt;br&gt; &amp;gt; *Sent:* Wednesday, July 01, 2009 5:51 PM &lt;br&gt; &amp;gt; *To:* ActiveDir@mail.activedir.org &lt;br&gt; &amp;gt; *Subject:* [ActiveDir] Exchange and Active Directory authentication &lt;br&gt; &amp;gt; confusion &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt;    I am having some confusion about Exchange authentication and Active &lt;br&gt; &amp;gt; Directory. We have a single forest with six domains that is Windows server &lt;br&gt; &amp;gt; 2003 R2SP2. The Exchange Server (2003) is in the root domain on a server &lt;br&gt; &amp;gt; that is not a domain controller. Two of the domains in our forest are remote &lt;br&gt; &amp;gt; sites connected via a T1 WAN link. &lt;br&gt; &amp;gt; &lt;br&gt; &amp;gt;   Recently the T1 link to one of our sites went down. As a result no one at &lt;br&gt; &amp;gt; the remote site could log into the Exchange server. This is understandable &lt;br&gt; &amp;gt; when the employees are on the site with the dead T1 connection. What &lt;br&gt; &amp;gt; confuses me is that none of the employees at this site could login to e-mail &lt;br&gt; &amp;gt; remotely via Outlook Web Access. Now if user accounts are replicated &lt;br&gt; &amp;gt; forest-wide? Then why could the users at the disconnected remote site not &lt;br&gt; &amp;gt; log into OWA via another domain controller (which authenticates users for &lt;br&gt; &amp;gt; the unreacheable remote server) not disconnected due to a out of service T1 &lt;br&gt; &amp;gt; WAN link? &lt;br&gt; &amp;gt; &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/0QRCXZIM2Sg/Default.aspx</link>
			<author>scharique</author>
			<pubDate>Thu, 02 Jul 2009 21:59:05 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35834/view/topic/Default.aspx</feedburner:origLink></item>
		<item>
			<title>RE: [ActiveDir] Exchange and Active Directory authentication
 confusion</title>
			<description>Agree with Brian. &lt;br&gt;  &lt;br&gt; Security boundary is the forest not the domain. &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; Thanks &lt;br&gt;  &lt;br&gt; Paul &lt;br&gt;  &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Brian Desmond &lt;br&gt; Sent: Thursday, July 02, 2009 3:17 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; Said explanation is 100% wrong. &lt;br&gt;  &lt;br&gt; Thanks, &lt;br&gt; Brian Desmond &lt;br&gt; brian@briandesmond.com &lt;br&gt;  &lt;br&gt; c - 312.731.3132 &lt;br&gt;  &lt;br&gt; Active Directory, 4th Ed - http://www.briandesmond.com/ad4/ &lt;br&gt; Microsoft MVP - https://mvp.support.microsoft.com/profile/Brian &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Thursday, July 02, 2009 3:13 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt;   This forest domain design was done before my time by a consultant. It is a very odd design. All of the domains are flat rather than parent child hierarchical. The explanation for this was better security. If anyone compromised one domain it would be more difficult to get access to the other domains. I am somewhat skeptical of this explanation. This is a K-12 environment so there is the possibility of malicious end users. &lt;br&gt;   The next iteration to 2008 server I hope to migrate to the one forest one domain design that seems to be the consensus for  better and easier  maintenance? &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of joe &lt;br&gt; Sent: Thursday, July 02, 2009 5:26 AM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; Have a domain controller for every domain you want authentication to be available for in the locations you want it available. &lt;br&gt;  &lt;br&gt; Alternately, get collapse the six domains down to one, you likely don't really need six domains. &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 6:31 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;   Thank you for clearing this up for me. Another hole in my knowledge has been patched! Are there any workarounds for this limitation? &lt;br&gt;  &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of joe &lt;br&gt; Sent: Wednesday, July 01, 2009 3:03 PM &lt;br&gt; To: activedir@mail.activedir.org &lt;br&gt; Subject: RE: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;  &lt;br&gt; The security information to authenticate/authorize a user is not replicated forest wide. A user can only be authenticated by a domain controller for the domain they are a member of. So say you have one DC for DomainXYZ and it went down, even though you have 100 DCs for DomainPDQ not a single DomainXYZ user could logon. &lt;br&gt;  &lt;br&gt;  &lt;br&gt; -- &lt;br&gt; O'Reilly Active Directory Fourth Edition - http://www.joeware.net/win/ad4e.htm &lt;br&gt;  &lt;br&gt;  &lt;br&gt;  &lt;br&gt; ________________________________ &lt;br&gt; From: activedir-owner@mail.activedir.org [mailto:activedir-owner@mail.activedir.org] On Behalf Of Dave &lt;br&gt; Sent: Wednesday, July 01, 2009 5:51 PM &lt;br&gt; To: ActiveDir@mail.activedir.org &lt;br&gt; Subject: [ActiveDir] Exchange and Active Directory authentication confusion &lt;br&gt;    I am having some confusion about Exchange authentication and Active Directory. We have a single forest with six domains that is Windows server 2003 R2SP2. The Exchange Server (2003) is in the root domain on a server that is not a domain controller. Two of the domains in our forest are remote sites connected via a T1 WAN link. &lt;br&gt;   Recently the T1 link to one of our sites went down. As a result no one at the remote site could log into the Exchange server. This is understandable when the employees are on the site with the dead T1 connection. What confuses me is that none of the employees at this site could login to e-mail remotely via Outlook Web Access. Now if user accounts are replicated forest-wide? Then why could the users at the disconnected remote site not log into OWA via another domain controller (which authenticates users for the unreacheable remote server) not disconnected due to a out of service T1 WAN link? &lt;br&gt;  &lt;br&gt; </description>
			<link>http://feedproxy.google.com/~r/ListArchives/~3/gFu5zGSvew8/Default.aspx</link>
			<author>pbbergs</author>
			<pubDate>Thu, 02 Jul 2009 21:48:57 GMT</pubDate>
		<feedburner:origLink>http://www.activedir.org/ListArchives/tabid/55/forumid/1/postid/35833/view/topic/Default.aspx</feedburner:origLink></item>
	</channel></rss>
